Bug 1008279 (CVE-2013-1443) - CVE-2013-1443 python-django: DoS via large passwords
Summary: CVE-2013-1443 python-django: DoS via large passwords
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2013-1443
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1008281 1008282 1009258
Blocks: 1008285
TreeView+ depends on / blocked
 
Reported: 2013-09-16 05:02 UTC by Ratul Gupta
Modified: 2019-09-29 13:08 UTC (History)
21 users (show)

Fixed In Version: Django 1.4.8, Django 1.5.4
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2014-11-14 17:50:46 UTC
Embargoed:


Attachments (Terms of Use)

Description Ratul Gupta 2013-09-16 05:02:55 UTC
It was found that python-django, a high level Python web framework, was vulnerable to a DoS attack via large passwords, where an attacker could send a large password to the machine, as there wasn't any limit imposed on the length of passwords, a large password could use all the machine's available resources for the hash computation, thus making the machine slow and unresponsive.

The issue has been known to be fixed in latest updates for python-django 1.4.8 and 1.5.4.

References:

https://www.djangoproject.com/weblog/2013/sep/15/security/
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=723043

Comment 1 Ratul Gupta 2013-09-16 05:12:57 UTC
Created Django14 tracking bugs for this issue:

Affects: epel-6 [bug 1008282]

Comment 2 Ratul Gupta 2013-09-16 05:13:19 UTC
Created python-django tracking bugs for this issue:

Affects: fedora-all [bug 1008281]

Comment 3 Lon Hohberger 2013-09-17 14:27:52 UTC
This needs clones for openstack-3 and openstack-rdo...

Comment 4 Garth Mollett 2013-09-18 04:27:38 UTC
(In reply to Lon Hohberger from comment #3)
> This needs clones for openstack-3 and openstack-rdo...

Lon, I've just triaged this for openstack and I belive we are not affected as keystone imposes a 4k limit on passwords.

Unless you think there is somewhere else this is exposed?

Comment 7 Fedora Update System 2013-09-24 22:56:17 UTC
python-django-1.5.4-1.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 8 Fedora Update System 2013-09-24 23:04:52 UTC
python-django14-1.4.8-1.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 9 Fedora Update System 2013-10-01 17:35:25 UTC
Django14-1.4.8-1.el6 has been pushed to the Fedora EPEL 6 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 10 Lon Hohberger 2013-10-04 17:43:20 UTC
Ok, Garth - I wasn't certain; it just looked like we were affected based on versioning.  Thanks!


Note You need to log in before you can comment on or make changes to this bug.